Skip to content
slide-deck.io
BlogGet started free

August 15, 2026

How to Present Audit Findings to Management

Audit findings presentations fail in two opposite ways: they are either so diplomatic that management doesn't understand the severity of the issues, or so adversarial that the presentation generates defensiveness and resistance rather than remediation. The goal of the audit presentation is not to prosecute management — it is to produce action that reduces organizational risk.

That goal requires a specific kind of discipline: findings presented with enough clarity that the severity is unmistakable, framed in a way that makes remediation feel achievable rather than shameful, and structured so that the management response is the logical conclusion of the meeting rather than a defensive afterthought.

Know Your Audience's Risk Tolerance Before You Present

Different management audiences receive audit findings differently. A CFO who has been through multiple audit cycles will engage with risk ratings and control gaps with relative equanimity. A department head who has never been audited may experience findings as an accusation, regardless of how they are framed.

Before the presentation, understand:

  • Which findings will land as surprising versus expected?
  • Which findings touch politically sensitive areas — projects with executive sponsorship, processes that reflect recent strategic decisions?
  • Which members of the audience are most likely to respond defensively, and why?

This is not about softening findings to protect feelings. It is about delivering findings in a way that the audience can hear and act on rather than dismiss and defend against.

The Risk Rating System

Every finding should carry a risk rating before you discuss the finding itself. Ratings vary by organization — High/Medium/Low is common; Critical/High/Medium/Low for organizations with more granular risk frameworks — but the rating must be defined consistently and applied consistently.

State the rating criteria at the beginning of the presentation. What makes a finding High versus Medium? Typically: likelihood of occurrence and magnitude of impact if it occurs. A finding that is likely to occur but has limited financial or operational impact might be Medium. A finding with low probability but catastrophic potential impact might still be High.

Consistent, defined risk ratings protect auditors from accusations that they rated findings punitively and give management a legitimate basis for prioritizing remediation.

Finding Slide Structure

Each finding should occupy its own slide. The structure:

Finding title: Brief, factual — "Privileged Access Reviews Not Completed Per Policy" not "Access Review Failures"

Risk rating: Prominently placed, consistently formatted

Observation: What did you find? What evidence supports the finding? Be specific — "23 of 40 privileged accounts sampled had not been reviewed in the 90-day window required by policy" rather than "access reviews are not consistently performed."

Risk: If left unaddressed, what is the exposure? Regulatory risk (cite the specific requirement), financial risk (estimated impact range), operational risk (what failure modes does this enable)?

Root cause: Why did this occur? Findings that address root cause produce sustainable remediation. Findings that describe only symptoms produce band-aid responses.

Recommendation: What should management do? Be specific — "Implement monthly access review reporting to the CISO with escalation for accounts overdue by 30+ days" rather than "strengthen access controls."

The observation and recommendation must be clearly separated. Mixing observation with recommendation produces findings that read as prosecution rather than analysis.

The Finding Distribution Slide

Before walking through individual findings, present the full finding landscape in a single summary slide: a risk-rating distribution matrix or simple count. "This audit identified 2 High, 5 Medium, and 3 Low findings."

This slide does two things: it previews the conversation and prepares the audience emotionally for what is coming, and it establishes the scope so management can see the full picture before diving into individual findings.

If the finding count is significantly higher than prior audit cycles, acknowledge it. If it reflects a new audit scope or a post-incident deep dive, say so. If it reflects genuine deterioration in the control environment, say that too — clearly.

Management Response Integration

The most effective audit presentations create space for management response during the meeting, not just in the written report. This requires sharing draft findings in advance — typically 5–7 business days before the presentation — and inviting management to validate observations, correct factual errors, and provide preliminary response.

During the presentation, for each finding:

  • State the observation and recommendation
  • Invite management to confirm or correct the observation
  • Capture the remediation commitment — owner, timeline, and specific action

A management response that says "we agree with the finding and will implement monthly access reviews by Q1, with the IT Compliance Manager as owner" is a substantively better outcome than a management response that says "we will review this finding and respond appropriately."

Push for specificity during the meeting. Vague commitments are hard to track and easy to not implement.

Handling Disagreement

Management teams sometimes disagree with findings — either the observation itself or the risk rating. This is legitimate and should be addressed professionally.

If management disputes an observation: hear the dispute, note it on the slide, and commit to validating the additional information before finalizing the report. Do not defend the observation under pressure if you haven't seen the evidence they are citing.

If management disputes the risk rating: explain the criteria that drove your rating. If the rating was applied consistently with your criteria, hold it. If management provides context that genuinely changes the risk assessment, adjust it. Audit credibility depends on consistent application of criteria — changing ratings to accommodate management preference without new information damages that credibility.

If management disputes the recommendation: distinguish between disagreeing with the recommendation and accepting a different approach to achieving the same risk reduction. An alternative remediation that achieves equivalent risk reduction is acceptable. An alternative that reduces the finding's visibility without reducing the risk is not.

The Close: Tracking and Accountability

End with a remediation tracking summary: all findings, their risk ratings, the committed owner, the committed completion date, and the next scheduled follow-up. This slide transforms the presentation from a report on the past into a plan for the future.

State the follow-up process: when will internal audit validate remediation, what evidence will be required to close each finding, and what happens to findings that are not remediated on schedule.

Audit findings that produce this level of specific commitment and visible tracking accountability produce better remediation rates than findings that go into a report and await the next audit cycle. The goal is a control environment that improves — and that requires a tracking structure that makes improvement visible and non-completion visible in equal measure.

Build your next presentation with AI

Generate editable .pptx decks in minutes. Free to start — no card required.

Try it free →